{"id":47935,"date":"2022-08-11T00:00:00","date_gmt":"2022-08-11T00:00:00","guid":{"rendered":"urn:uuid:dc0c4bf9-c1e5-ad0c-3bed-b48defa6e1f4"},"modified":"2022-08-11T00:00:00","modified_gmt":"2022-08-11T00:00:00","slug":"copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/","title":{"rendered":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/COVER-copperstealer-distribute-malicious-chrome-browser-extension-to-steal-crypto.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users\u2019 wallet account information via a malicious Chromium-based browser extension.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"malware,endpoints,cyber crime,privacy &amp; risks,articles, news, reports,cyber threats\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2022-08-11\"> <meta property=\"article:tag\" content=\"malware\"> <meta property=\"article:section\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html\"> <title>CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html\"><br \/>\n<meta property=\"og:title\" content=\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies\"><br \/>\n<meta property=\"og:description\" content=\"We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users\u2019 wallet account information via a malicious Chromium-based browser extension.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/COVER-copperstealer-distribute-malicious-chrome-browser-extension-to-steal-crypto.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies\"><br \/>\n<meta name=\"twitter:description\" content=\"We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users\u2019 wallet account information via a malicious Chromium-based browser extension.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/COVER-copperstealer-distribute-malicious-chrome-browser-extension-to-steal-crypto.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.075349139331\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"2131146998\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"8.793893129771\">\n<div class=\"article-details\" role=\"heading\" readability=\"37.129770992366\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Malware<\/p>\n<p class=\"article-details__description\">We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users\u2019 wallet account information via a malicious Chromium-based browser extension.<\/p>\n<p class=\"article-details__author-by\">By: Jaromir Horejsi, Joseph C Chen <time class=\"article-details__date\">August 11, 2022<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"39.764009471192\">\n<div readability=\"26.828729281768\">\n<p>We published our analyses on CopperStealer distributing malware by abusing various components such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/websites-hosting-fake-cracks-spread-updated-copperstealer.html\">browser stealer<\/a>, <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/c\/websites-hosting-cracks-spread-malware-adware.html\">adware browser extension<\/a>, or remote desktop. Tracking the cybercriminal group\u2019s latest activities, we found a malicious browser extension capable of creating and stealing API keys from infected machines when the victim is logged in to a major cryptocurrency exchange website. These API keys allow the extension to perform transactions and send cryptocurrencies from victims\u2019 wallets to the attackers\u2019 wallets.<\/p>\n<p>Similar to previous routines, this new component is spread via fake crack (also known as warez) websites. The component is usually distributed in one dropper together with a browser stealer and bundled with other unrelated pieces of malware. This bundle is compressed into a password-protected archive and has been distributed in the wild since July.<\/p>\n<p><span class=\"body-subhead-title\">Dropper\/Extension installer<\/span><\/p>\n<p>This component uses the same cryptor described in <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/f\/websites-hosting-fake-cracks-spread-updated-copperstealer.html\">previous posts<\/a> in the first stage, followed by the second stage wherein the decrypted DLL is Ultimate Packer Executables-(UPX) packed. After decrypting and unpacking, we noticed a resource directory named <i>CRX<\/i> containing a 7-Zip archive. Malicious Chrome browser extensions are usually packaged this way.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure1-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig1-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 1. Extension installer called CRX containing a 7-Zip archive<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The archive contains a JSON file with settings and another 7-Zip archive with the code of the extension installer itself.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure2-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig2-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 2. Unpacked content of CRX<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"44\">\n<div readability=\"33\">\n<p>The extension installer first modifies the files <i>Preferences<\/i> and <i>Secure Preferences<\/i> in the Chromium-based browser\u2018s <i>User Data<\/i> directory. The file, named <i>Preferences<\/i>, is in JSON format and contains individual user settings. The extension installer switches off browser notifications.<\/p>\n<p>Meanwhile, the file named <i>Secure Preferences<\/i> is also in JSON format and contains the installed extension\u2019s settings. For a newly installed extension, the content of <i>crx.json<\/i> file is inserted into this <i>Secure Preferences<\/i> settings file. A newly installed extension is also added to the extension installation allow list located in the registry.<\/p>\n<p>The files from the <i>crx.7z<\/i> archive are then extracted into the extension\u2019s directory located in &lt;<i>User Data\\Default\\Extension<\/i>&gt;. Finally, the browser restarts so the newly installed extension becomes active. We analyzed that the targeted browsers are Chromium-based and include:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Chrome<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Chromium<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Edge<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Brave<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Opera<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C\u1ed1c C\u1ed1c<\/span><\/li>\n<li><span class=\"rte-red-bullet\">CentBrowser<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Iridium<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Vivaldi<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Epic<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Coowon<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Avast Secure Browser<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Orbitum<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Comodo Dragon<\/span><\/li>\n<\/ul>\n<p>We also noted that the extension was installed to the victims\u2019 browsers with two different extension IDs, and neither can be found on the official Chrome Web Store:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">cbnmkphohlaaeiknkhpacmmnlljnaedp<\/span><\/li>\n<li><span class=\"rte-red-bullet\">jikoemlnjnpmecljncdgigogcnhlbfkc<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">Analysis of the extension<\/span><\/p>\n<p>After the extension\u2019s installation, we also noticed the following newly installed extension in <i>chrome:\/\/extensions\/<\/i>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure3-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig3-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 3. Installed malicious extension<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>The extension manifest defines two Java Scripts. The background script is named <i>background.js<\/i> and runs inside the extension itself in only one instance. Meanwhile, the content script is called <i>content.js<\/i> and runs in the context of coinbase.com, as shown in snippet from the extension manifest.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure4-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig4-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 4. Settings of the content script as specified in the extension manifest<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p><b>Script obfuscation<\/b><\/p>\n<p>Both Javascript files are heavily obfuscated. In the first obfuscation step, all strings are split into substrings, stored in a single array, and access to the array is achieved by calling multiple hexadecimal-named functions with five hexadecimal integer parameters.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure5-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig5-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 5. The first layer of obfuscation<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"38\">\n<div readability=\"21\">\n<p>Looking at the second obfuscation step, all the strings, logic operators (+, -, *, \/), function calls, among others are inserted into an array of objects. Each object has a random string as a name, and either another string or function as a value. In the example we analyzed, <i>_0x1f27e3[&#8216;PFPYr&#8217;]<\/i> corresponds to string \u201cset\u201d, and <i>_0x1f27e3[&#8216;LYLfc&#8217;](0,1)<\/i> corresponds to the logic expression 0!=1.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure6-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig6-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 6. The second layer of obfuscation<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"43.576182136602\">\n<div readability=\"32.682136602452\">\n<p>Both obfuscation steps can be deobfuscated by using custom automation scripts.<\/p>\n<p><b>Background script analysis<\/b><\/p>\n<p>Analyzing the scripts, this section breaks down how the cybercriminals are able to steal the account information of legitimate cryptocurrency wallet users. When the extension starts, the background script makes two queries. The first one is a GET request to <i>http:\/\/&lt;C&amp;C server&gt;\/traffic\/chrome<\/i>, likely for statistical purposes. The second query is a POST request to <i>http:\/\/ &lt;C&amp;C server&gt;\/traffic\/domain<\/i>, wherein the data contains the domains of cryptocurrency-related websites based on the cookies found in the machine:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">blockchain.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">coinbase.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">binance.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ftx.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">okex.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">huobi.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">kraken.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">poloniex.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">crypto.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">bithumb.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">bitfinex.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">kucoin.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">gate.io<\/span><\/li>\n<li><span class=\"rte-red-bullet\">tokocrypto.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">tabtrader.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mexc.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">lbank.info<\/span><\/li>\n<li><span class=\"rte-red-bullet\">hotbit.io<\/span><\/li>\n<li><span class=\"rte-red-bullet\">bit2me.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">etoro.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">nicehash.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">probit.com<\/span><\/li>\n<\/ul>\n<p>Then the extension defines an array of the threat actor\u2019s addresses for various cryptocurrencies and tokens for:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Tether (USDT, specifically in Ethereum ERC20 and TRON TRC20)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Ethereum (ETH)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Bitcoin (BTC)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Litecoin (LTC)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Binance coin (BNB)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Ripple (XRP)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Solana (SOL)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Bitcoin Cash (BCH)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Zcash (ZEC)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Stellar Lumens (XLM)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dogecoin (DOGE)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Tezos (XTZ)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Algorand (ALGO)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Dash (DASH)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Cosmos (ATOM)<\/span><\/li>\n<\/ul>\n<p>For ETH addresses, the script hardcodes about 170 additional ERC20-based tokens. Afterward, the extension starts <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/runtime\/#event-onMessage\">onMessage<\/a> listener to listen for messages sent from either an extension process&nbsp; or a content script. The message is in JSON format, with one of the name-value pair called <i>method<\/i>. The background script listens for the following methods:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Method \u201chomeStart\u201d<\/span><\/li>\n<\/ul>\n<p>This method tries to obtain the API key (<i>apiKey<\/i>) and API secret (<i>apiSecret<\/i>) from Chrome\u2019s <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/storage\/\">local storage<\/a> if these key-secret pairs were previously obtained and saved. These parameters are needed for the following steps:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Uses the API to get information about wallets, addresses, and balances by requesting <i>\/api\/v2\/accounts<\/i>. The result of this request is also exfiltrated to <i>http:\/\/&lt;C&amp;C server&gt;\/traffic\/step<\/i>.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">If the request is successful, the API sends \u201cokApi\u201d message to content script and starts parsing for wallet information. If the wallet balance is non-zero, it attempts to send 85% of the available funds to the attacker-controlled wallet.<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure7-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig7-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 7. Looking for wallets with non-zero balance<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure8-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig8-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 8. Stealing 85% of available funds<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35.468680089485\">\n<div readability=\"18.213646532438\">\n<p>The result of the transaction request is also exfiltrated to <i>http:\/\/&lt;C&amp;C server&gt;\/traffic\/step<\/i>.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><\/span>If not successful, the API sends a \u201cerrorApi\u201d message to the content script. The \u201cerrorApi\u201d message contains a CSRF token from <a href=\"https:\/\/www.coinbase.com\/settings\/api\"><i>https:\/\/www.coinbase.com\/settings\/api<\/i><\/a> as one parameter, and a response to the new API key creation request.<\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">Method \u201ccreateApi\u201d<\/span><\/li>\n<\/ul>\n<p>This message is received from the content script and contains a two-factor authentication (2FA) code as one of the parameters. This code is used for opening a new modal window for creating API keys. Typically, when you click on \u201c+New API Key\u201d in the Coinbase API settings, a 2FA code is requested and if the code is correct, the modal window appears.<\/p>\n<p>In the second step of the new API creation, one needs to select wallets and their permissions. The malicious extension requests all the available permissions for all accounts.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure9-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig9-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 9. Selecting all accounts and permissions<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"44.805288461538\">\n<div readability=\"34.848557692308\">\n<p>Afterward, one needs to insert one more authentication code and a form with the newly generated API keys is displayed. If successful, the background script then continues with extracting two API keys (API Key and API Secret) from the \u201cAPI key details\u201d form, saves them to Chromium\u2019s local storage for later use, and exfiltrates them to <i>http:\/\/&lt;C&amp;C server&gt;\/traffic\/step<\/i>. If API authentication is not successful, a \u201cretryApi\u201d message is sent to content script.<\/p>\n<p><span class=\"body-subhead-title\">Content script analysis<\/span><\/p>\n<p>We looked further into the content script to analyze the routine responsible for stealing the 2FA passwords from the victims. The content script contains a list of messages in the following languages:&nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">English (en)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">German (de)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Spanish (es)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">French (fr)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Japanese (jp)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Indonesia (id)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Italian (it)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Polish (pl)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Portuguese (pt)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Russian (ru)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Thai (th)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Turkish (tr)<\/span><\/li>\n<\/ul>\n<p>Each message contains a title, description, and error message for both phone and authenticator.<\/p>\n<p>For \u201cphone,\u201d displayed messages in English appear as:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">\u201ctitle\u201d: \u201cPlease enter the verification code from your phone.\u201d<\/span><\/li>\n<li><span class=\"rte-red-bullet\">\u201cdescription\u201d: \u201cEnter the two-step verification code provided by SMS to your phone.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">\u201cmessage\u201d: \u201cThat code was invalid. Please try again.\u201d<\/span><\/li>\n<\/ul>\n<p>For \u201cauthenticator,\u201d displayed messages in English look like:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">\u201ctitle\u201d: \u201cPlease enter the verification code from your authenticator.\u201d<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&nbsp;\u201cdescription\u201d: \u201cEnter the 2-step verification code provided by your authentication app.\u201d<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&nbsp;\u201cmessage\u201d: \u201cThat code was invalid. Please try again.\u201d<\/span><\/li>\n<\/ul>\n<p>The content script initially makes a request to <i>\/api\/v3\/brokerage\/user_configuration<\/i> to see if a user is logged in or not. The script then sends a \u201chomeStart\u201d message to the background script and starts listening using <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/runtime\/#event-onMessage\">onMessage<\/a> to listen for \u201cmethod\u201d attributes similar to the background script routine. If it receives a message with a method attribute<i> equal to \u201cokApi\u201d<\/i>, it hides the code loader and removes the modal window. If it receives a message with a method attribute equal to<i> \u201cerrorApi\u201d<\/i> it then creates a modal window.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure10-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig10-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 10. Displayed modal window asking for entering authentication code<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36.132374100719\">\n<div readability=\"17.818705035971\">\n<p>The modal window has input boxes and listens for <a href=\"https:\/\/www.w3schools.com\/jsref\/event_oninput.asp\">oninput<\/a> events. If each of the input boxes contains one digit, they are concatenated into one \u201ctfa\u201d (2FA) variable and sent as a parameter of \u201ccreateApi\u201d message to the background script. The code loader is also shown.<\/p>\n<p>The modal window has six input boxes for six digits, provided when using an authenticator. If the victim uses an authentication via SMS, then the authentication code has seven digits, and the modal window will have one more input box. This logic is implemented in the modal window code. The received message with <i>method attribute equal to \u201cretryApi\u201d <\/i>deletes all inserted digits and displays an error message in red.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/figure11-copperstealer-distributes-malicious-chromium-browser-extension-steal-crypto.png\" alt=\"fig11-copperstealer-update-distribute-malicious-chromium-browser-extension-for-crypto\"><figcaption>Figure 11. After the authentication code is entered, an error message appears<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"42.381450488145\">\n<div readability=\"29.916317991632\">\n<p><span class=\"body-subhead-title\">Conclusion<\/span><\/p>\n<p>The cybercriminals behind CopperStealer are far from stopping anytime soon, and we continue monitoring their deployments as they find more ways to target unwitting victims. While analyzing this routine, we found multiple similarities between this extension and the previously reported malware components, one of which is that the malicious extension and CopperStealer were distributed from the same dropper and by the same delivery vector that we have documented previously.<\/p>\n<p>Another striking similarity is the malicious extension\u2019s command and control (C&amp;C) domain having the same format as the Domain Generation Algorithm (DGA) domains tracked back as belonging to the previous versions of CopperStealer. The format is a string composed of 16 hexadecimal characters. Moreover, both of their C&amp;C servers were constructed with the PHP framework \u201cCodeIgniter.\u201d These attributes hint to us that the developers or operators behind the malware and the extension could be associated.<\/p>\n<p>Users and organizations are advised to download their software, applications, and updates from the official platforms to mitigate the risks and threats brought by malware like CopperStealer. Teams are advised to keep their security solutions patched to ensure that detection and prevention solutions can protect systems from possible multiple attacks and infections.<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise (IOCs)<\/span><\/p>\n<p>You will find the list of the IOCs <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/IOCs-CopperStealer-distributes-malicious-Chromium-browser-extension-steal-crypto.txt\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users\u2019 wallet account information via a malicious Chromium-based browser extension. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":47936,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9521,9511,9508,9513,9536],"class_list":["post-47935","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-crime","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-endpoints","tag-trend-micro-research-malware","tag-trend-micro-research-privacyrisks"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-11T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/COVER-copperstealer-distribute-malicious-chrome-browser-extension-to-steal-crypto.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies\",\"datePublished\":\"2022-08-11T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/\"},\"wordCount\":1878,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Crime\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Privacy&amp;Risks\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/\",\"name\":\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png\",\"datePublished\":\"2022-08-11T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png\",\"width\":605,\"height\":85},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/","og_locale":"en_US","og_type":"article","og_title":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-08-11T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/h\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/COVER-copperstealer-distribute-malicious-chrome-browser-extension-to-steal-crypto.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies","datePublished":"2022-08-11T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/"},"wordCount":1878,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/08\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Crime","Trend Micro Research : Cyber Threats","Trend Micro Research : Endpoints","Trend Micro Research : Malware","Trend Micro Research : Privacy&amp;Risks"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/","url":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/","name":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/08\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png","datePublished":"2022-08-11T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/08\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/08\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies.png","width":605,"height":85},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/copperstealer-distributes-malicious-chromium-based-browser-extension-to-steal-cryptocurrencies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47935"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47935\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/47936"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}